Staff Principal Software Engineer Security
AI app builder that turns natural-language prompts into full-stack web applications.
Maintainer signals as of 8/14/2026
About Lovable
Lovable (lovable.dev) is a Swedish AI software-builder platform: users describe an app in natural language and Lovable generates production full-stack code — one of the fastest-growing AI products.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build end-to-end security product features, including audit flows, security scanner interfaces, compliance tooling, and static analysis. You will integrate AI and LLM capabilities into security workflows to detect, explain, and remediate vulnerabilities. You will work across the full stack, own work from the first commit through production, conduct security-focused code reviews, advocate for secure coding practices, and influence technical direction and product strategy with a security-first mindset.
Requirements
- Have 10+ years of engineering experience shipping production-grade products at high velocity and operating at senior engineering levels.
- Demonstrate deep command of React and TypeScript on the frontend and Golang on the backend.
- Have experience with product security features or code security and static analysis, such as SAST, linters, or vulnerability scanners.
- Understand systems design, performance tradeoffs, and scalable architecture.
- Demonstrate product sense for making complex functionality simple and actionable.
- Be familiar with AI or LLM-powered tooling, or have a background in dense algorithmic or systems work.
- Be comfortable navigating ambiguity and driving organisational clarity.
- Be based in Stockholm or be ready to relocate.
Responsibilities
- Build end-to-end security product features, including audit flows, security scanner interfaces, compliance tooling, and static analysis.
- Integrate AI and LLM capabilities into security workflows to detect, explain, and remediate vulnerabilities.
- Ship full-stack work and own it from the first commit through production.
- Advocate for secure coding practices and conduct security-focused code reviews.
- Influence technical direction and product strategy with a security-first mindset.
